Vulnerabilities in OpenVPN and SoftEther VPN

OpenVPN 2.6.7 has been released, a package for creating virtual private networks that allows for encrypted connections between two client machines or enables the operation of a centralized VPN server for multiple clients concurrently. This new version addresses two vulnerabilities:

  • CVE-2023-46850 - accessing memory after it has been freed (use-after-free) may result in sending process memory content to the other end of the connection, and potentially lead to remote code execution. The issue occurs in configurations using TLS (run without the "—secret" parameter).
  • CVE-2023-46849 - the occurrence of a division by zero situation can lead to remote triggering of access server crashes in configurations using the "—fragment" option.

From non-security-related changes in OpenVPN 2.6.7:

  • A warning has been added when another side sends DATA_V1 packets while attempting to connect OpenVPN 2.6.x clients to incompatible servers based on versions 2.4.0-2.4.4 (to resolve compatibility issues, the "—disable-dco" option can be used).
  • The deprecated method tied to OpenSSL 1.x that uses the OpenSSL Engine to load keys has been removed. The reason cited is the author's unwillingness to relicense the code with new binding exceptions.
  • A warning has been added when a p2p NCP client connects to server p2mp (a combination used to operate without cipher negotiation), as there are issues when using version 2.6.x on both sides of the connection.
  • A warning has been added stating that the "—show-groups" flag does not display all supported groups.
  • In the "—dns" parameter, the processing of the "exclude-domains" argument, which appeared in branch 2.6 but is not yet supported by backends, has been removed.
  • A warning is displayed if the INFO control message is too large to be forwarded to the client.
  • Support for the CMake build system has been added for builds using MinGW and MSVC. Support for the old MSVC build system has been removed.

Additionally, it is notable that 9 vulnerabilities have been identified in the open VPN-On the SoftEther server. One of the issues (CVE-2023-27395) has been assigned a critical danger level — the vulnerability is caused by a buffer overflow and can lead to remote code execution on the client side when attempting to connect to a server controlled by an attacker. The vulnerability has been patched in the June update of SoftEther VPN 4.42 Build 9798 RTM. Two other vulnerabilities (CVE-2023-32634, CVE-2023-27516) allow unauthorized access to the VPN session during a MITM attack using the default credentials for the RPC server. The vulnerabilities have been addressed in a patch.

The vulnerabilities CVE-2023-31192 and CVE-2023-32275 (patch) may lead to the leakage of sensitive information in certain packets as a result of MITM attacks. The remaining 4 vulnerabilities (CVE-2023-22325, CVE-2023-23581, CVE-2023-22308, and CVE-2023-25774) can be exploited to cause denial of service, such as forcibly dropping the connection or crashing the client. Recently, the codebase of SoftEther VPN also received a fix for 7 vulnerabilities, details of which are not yet available.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster